PlumbTrackLive demoGRC Risk System

← internal audit

Audit — AU-10 — Non-repudiation

Framework: NIST SP 800-53 Rev.5 AU-10 · Mark each check Pass / Fail / N/A; a Fail is a finding to remediate. · open the item

0 pass · 0 finding(s) · 0 N/A · 0 of 6 checked
Examine Examine system design and configuration to confirm actions are bound to a unique individual identity (unique named accounts, no shared credentials) so that an actor cannot later deny having performed a logged action.
Test Perform an action as a specific user and confirm the resulting audit trail attributes it unambiguously and irrefutably to that individual's identity.
Examine Examine use of digital signatures or cryptographic binding for designated critical transactions, records, or documents to provide non-repudiation of origin (AU-10).
Interview Interview responsible personnel on how a user's identity is validated/bound before actions are attributed to them (identity binding, AU-10(1)), and how that binding is preserved in the record.
Test Test that shared, generic, or service accounts are prohibited for interactive privileged actions, or are otherwise reliably mapped back to a responsible individual, so actions cannot be repudiated.
Examine Examine that trusted, synchronized time-stamping and log integrity protection support non-repudiation of when an attributed action occurred.